AEOS Vulnerability Management: SAQ Requirements and Customs Audit

Gestione Vulnerabilita e Requisiti QAV per Status AEOS

To obtain and maintain AEOS (Security) status, companies must demonstrate that they actively manage cyber vulnerabilities. It is not enough to simply declare the use of firewalls and antivirus software: customs authorities require concrete evidence of a periodic process for identifying and remediating security flaws.

What the Self-Assessment Questionnaire (SAQ) requires

Section 3.7.1 of the SAQ asks to describe the measures taken to protect systems from intrusions and whether periodic vulnerability management is performed. The explanatory notes specify that you must indicate:

  • Who performs vulnerability management
  • How frequently tests against unauthorized access are conducted
  • What corrective measures have been adopted when critical issues emerge

This requirement is not merely formal: it responds to Article 25, paragraph 1, letter j) of the UCC Implementing Regulation, which mandates that the AEO protect its computer system from unauthorized manipulation.

Why cybersecurity is crucial for the customs supply chain

A vulnerable system exposes the entire logistics chain to concrete risks:

  • Manipulation of customs declarations: false data can alter the classification, value, or origin of goods
  • Loss of document integrity: information regarding shipments and cargo can be modified without a trace
  • Unauthorized access: facilitates the trafficking of illicit or dangerous goods through the supply chain

For this reason, customs authorities verify not only the existence of defensive measures but also the operator’s ability to detect and correct flaws in a timely manner.

From detection to remediation: what customs authorities verify

During the AEO audit, authorities do not expect systems to be free of vulnerabilities. Instead, they verify that the company has implemented a structured process:

  1. Periodic scanning: regular tests to identify known vulnerabilities in the infrastructure
  2. Risk assessment: classification of critical issues based on their impact on customs systems
  3. Remediation plan: documentation of the corrective measures taken and the timelines involved
  4. Audit trail: evidence demonstrating the closure of critical vulnerabilities

A professional Vulnerability Assessment provides exactly this evidence: detailed reports, risk classification, and operational recommendations that can be presented during the customs audit. To understand how these tests fit into the broader context of AEO certification, it is important to consider the entire security framework required.

Frequently asked questions about vulnerability management for AEO

  • Is it mandatory to indicate who manages vulnerabilities in the SAQ?
  • Yes. Point 3.7.1 of the SAQ explicitly requires specifying whether vulnerability management is performed periodically and identifying the person responsible for the function. This information is verified during the on-site audit.
  • How do vulnerability tests meet the criteria of Section 3.7?
  • Vulnerability tests provide technical proof that the company has adopted measures against unauthorized intrusions, as required by Article 25 of the Implementing Regulation, and actively monitors the effectiveness of defensive barriers.
  • What is the difference between a Vulnerability Assessment and a Penetration Test?
  • A Vulnerability Assessment is a systematic scan of known vulnerabilities present in the infrastructure. A Penetration Test simulates a real attack to verify whether those vulnerabilities can actually be exploited to compromise the system.
  • Is it necessary to demonstrate the closure of detected vulnerabilities?
  • Yes. The SAQ explanatory notes state that when tests detect critical issues, the operator must provide documentary evidence of the corrective measures taken and their effectiveness.
  • Does an ISO 27001 certificate replace technical vulnerability management?
  • No. ISO 27001 certification attests to the existence of a security management system, but customs authorities verify the concrete application of technical controls on the infrastructure handling customs data during the AEO audit.

Systematic vulnerability management is not just a documentary requirement: it represents a fundamental operational requirement to protect the logistics chain and maintain AEOS status over time. In addition to technical tests, it is essential to implement security governance that coordinates all aspects of cyber protection required by AEO regulations.

Related insights

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!